Agent skill

Plan Review

by sd0xdev in sd0xdev/sd0x-harness

Pre-ExitPlanMode adversarial plan review loop via Codex exec.

MITAuto-check passedAgent Workflows

Install Plan Review

skills CLI
$ npx skills add sd0xdev/sd0x-harness --skill plan-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sd0xdev/sd0x-harness plan-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/plan-review .claude/skills/plan-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
plan-review
GitHub stars
192
Token cost
~3.9k tokens
SKILL.md length
1,592 words
Files
3 (incl. references)
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

Pre-ExitPlanMode adversarial plan review loop via Codex exec.

  • Works in 5 steps: Tier + round budget → Secret redaction (NFR-8, fail-closed) → Review dispatch (tier ladder) → …
  • Before presenting a plan to the user
  • SKILL.md covers Trigger, When NOT to Use, Boundary Contract (v1… and Arguments, plus 6 more sections
  • Calls node

What it does

Plan Review is an agent skill from sd0xdev/sd0x-harness. Pre-ExitPlanMode adversarial plan review loop via Codex exec. Use when: in plan mode, before presenting a plan to the user; reviewing an in-context plan draft. Not for: .md file review (use doc-review), code review (use codex-code-review), lifecycle spec review (use review-spec). Output: review trail summary + plan gate (✅ Plan Ready / ⛔ Plan Blocked / ⚠️ Plan Needs Human).

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/codex-prompt-plan.md` and `references/review-loop-plan.md`).

It sits in Agent Workflows, covering Code review and Planning. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.

When your agent uses it

  • Before presenting a plan to the user
  • Reviewing an in-context plan draft

Example prompts

  • “/plan-review”

Requirements

  • Pre-approved tools (allowed-tools): Bash(bash:*), Bash(git:*), Bash(node:*), Read, Grep, Glob, Task, Skill

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Tier + round budget
  2. Secret redaction (NFR-8, fail-closed)
  3. Review dispatch (tier ladder)
  4. Convergence (independent budget)
  5. Trail summary (FR-9 / NFR-4)

What it can do on your machine

Read from SKILL.md and the folder at commit a4d4bc1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(bash:*)
    • Bash(git:*)
    • Bash(node:*)
    • Read
    • Grep
    • Glob
    • Task
    • Skill

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Plan Review loads about 3.9k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 1,592 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sd0xdev/sd0x-harness at commit a4d4bc1, republished under its MIT licence (© sd0xdev). 1,592 words, ~3,891 tokens.

Download SKILL.mdSave it as .claude/skills/plan-review/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
plan-review
description
Pre-ExitPlanMode adversarial plan review loop via Codex exec. Use when: in plan mode, before presenting a plan to the user; reviewing an in-context plan draft. Not for: .md file review (use doc-review), code review (use codex-code-review), lifecycle spec review (use review-spec). Output: review trail summary + plan gate (✅ Plan Ready / ⛔ Plan Blocked / ⚠️ Plan Needs Human).
allowed-tools
Bash(bash:*), Bash(git:*), Bash(node:*), Read, Grep, Glob, Task, Skill

Plan Review Skill

Adversarial review gate for plan-mode drafts: the plan is challenged by an independent reviewer and revised until convergence before ExitPlanMode presents it to the user.

Trigger

  • Keywords: plan review, review plan, plan-review, pre-ExitPlanMode review
  • Self-invoke: in plan mode, before calling ExitPlanMode, when the project opts in via @rules/auto-loop-project.md ## Plan Review: enabled or the user asks for plan review

When NOT to Use

  • Reviewing .md files on disk (use /codex-review-doc — different artifact: filesystem path vs in-context plan text)
  • Reviewing lifecycle specs 1-requirements.md / 2-tech-spec.md (use /review-spec)
  • Code review (use /codex-review-fast)
  • Not in plan mode / no plan draft exists

Boundary Contract (v1 Acceptance Scope)

  • Review gate applies only when this skill is actually invoked (A1 skill-driven; enabled-but-unexecuted detection is v2).
  • Analysis-only: the reviewer surfaces findings; Claude revises the plan — the skill never rewrites or deletes plan content itself.
  • Review pass ≠ execution approval: the user still arbitrates the final plan after ExitPlanMode (FR-14 Won't).
  • Fully behaviour-layer: no hook parses plan-review output and no state file records the loop. The skill counts its own rounds in conversation, and the sentinels below are prose contracts the model and the human read — nothing mechanical routes on them (hook-lightweighting § 3.3).

Arguments

ArgBehavior
(none)tier = standard — Codex alone, with the fix → re-review loop
--quickSingle Codex pass, no loop
--dualAdds a secondary reviewer in parallel. Off unless passed — for a release or a security-sensitive plan, not routine planning
--deepDelegate to /codex-brainstorm (Nash equilibrium debate; attack/defense built-in)
--skip-reviewImmediate bypass: emit [PLAN_REVIEW_SKIPPED], present raw plan
--verboseRound-by-round trail (default: summary only)

User escape (NFR-5): any explicit "skip review" / "直接看 plan" instruction — detected at skill entry and before each re-review round — exits within ≤1 round, emits [PLAN_REVIEW_SKIPPED], and presents the current plan.

Workflow

mermaid
sequenceDiagram
    participant C as Claude (plan mode)
    participant RD as security-redact
    participant CX as Codex exec
    participant SA as Secondary (Task)

    C->>C: Step 1: tier + round counter (in conversation)
    C->>RD: Step 2 redaction contract
    alt high-confidence secret hit
        C->>C: [PLAN_REVIEW_DEGRADED] → ExitPlanMode (plan NOT sent to reviewer)
    else masked plan
        alt quick
            C->>CX: 1-pass review (references/codex-prompt-plan.md)
        else standard
            C->>CX: Codex review loop (save threadId)
            opt --dual
                C->>SA: Secondary perspective (parallel)
            end
        else deep
            C->>C: Skill("codex-brainstorm", plan challenge)
        end
        loop until ✅ Plan Ready or max_rounds (default 5)
            CX-->>C: findings + ## Plan Review sentinel
            C->>C: revise plan (author-side), increment round
            C->>CX: re-review (§ Resume, references/review-loop-plan.md)
        end
        alt converged
            C->>C: ✅ Plan Ready → trail summary → ExitPlanMode
        else max_rounds reached
            C->>C: ⚠️ Plan Needs Human + residual findings → user arbitrates
        else codex_fail (adapter exit 1)
            C->>C: [PLAN_REVIEW_DEGRADED] → ExitPlanMode
        end
    end
Step 1: Tier + round budget

Determine tier (standard default; --quick / --deep explicit) and the round cap: read ## Plan Review Max Rounds from rules/auto-loop-project.md directly (unset → 5). The round counter lives in this conversation — state the current round in each re-review dispatch ("round 2/5") so the count survives in the transcript. There is no state file to open and no script to run: the loop's bookkeeping is the skill's own.

Step 2: Secret redaction (NFR-8, fail-closed)

Apply the contract from scripts/security-redact.js (verified API — scanHighConfidence returns {name, fingerprint} | null, it does NOT throw):

js
const { scanHighConfidence, maskMediumConfidence } = require('./scripts/security-redact.js');
const high = scanHighConfidence(planText);   // {name, fingerprint} | null
if (high) {
  // fail-closed: plan is NOT sent to any reviewer
  // → output [PLAN_REVIEW_DEGRADED]; plan still delivered to user via ExitPlanMode
} else {
  send(maskMediumConfidence(planText));      // medium-confidence → [REDACTED] before send
}

Run via node -e against the plan text, feeding the text through stdin with a quoted heredoc — never as an argv literal:

bash
node -e '...' <<'PLAN_EOF_<random-hex>'
<plan text>
PLAN_EOF_<random-hex>

<random-hex> is a placeholder to be generated, not a value to copy. It is written this way deliberately: the rationale below is that "a fixed delimiter makes the attack a copy-paste", and an example carrying a concrete literal reinstates exactly that for anyone who copies rather than generates. Substitute a fresh suffix on every invocation, per the table that follows.

The delimiter must be freshly randomized per invocation, and you must verify it does not collide. Before emitting the command:

StepAction
1Generate a new random suffix (≥8 hex chars) → PLAN_EOF_<suffix>
2Scan the plan text for any line whose entire content (after stripping trailing whitespace) equals that delimiter
3On collision → regenerate and re-check. Never emit a command whose delimiter appears in the body

Rationale: argv leaks the un-redacted plan into system-wide process listings (ps); heredoc stdin never appears in argv. The quoted delimiter prevents shell interpolation of plan content — but quoting does not stop the plan from terminating the heredoc. A plan containing a bare line PLAN_EOF ends the here-document early, and every line after it is handed to the shell as commands under this skill's Bash permission. That is arbitrary command execution driven by plan text, which in this skill is frequently drafted from untrusted material (issue bodies, PR descriptions, pasted logs). A fixed delimiter makes the attack a copy-paste; a randomized-and-checked one makes it unreachable.

The plan draft already exists in the session transcript (it is in-context text), so the heredoc adds no new exposure surface — and handing this step its input through a file is not available, because the Write tool is what plan mode withholds. Step 3 writes the transport's prompt.md by this same heredoc for this same reason: an application of the reasoning here, not an exception to it. Forbidden anti-pattern: judging high-confidence via redact(text, {abortOnHigh: false}) return value (high is already masked, indistinguishable from medium).

Step 3: Review dispatch (tier ladder)
TierReviewerLoop
quickCodex exec ×11-pass
standard (default)Codex execfix → re-review (§ Resume)
deepSkill("codex-brainstorm", ...)brainstorm termination (Nash attack/defense)
  • First Codex call: dispatch per @skills/codex-code-review/references/codex-transport.md § Start with references/codex-prompt-plan.md — the transport pins the sandbox and approval policy, so no call site chooses them. Save the threadId.
  • prompt.md is written by heredoc here, not by the Write tool — this skill runs before ExitPlanMode, where Write is unavailable, so the transport reference names this skill as its one exemption and carries the two-command recipe (@skills/codex-code-review/references/codex-transport.md § Files), along with every file-lifecycle guarantee that goes with it. Follow it there; no other lifecycle guarantee is restated here — only that this skill writes the prompt by heredoc rather than by Write, which its own plan-mode workflow turns on.
  • The delimiter is generated per § Redaction's table but checked against a different payload: that step scans the plan text, while this heredoc carries the whole rendered prompt — template sections and plan together. Scan the exact bytes going into prompt.md.
  • What is rendered into it is the redaction step's output, never planText. Under the MCP envelope the redaction boundary and the send were the same act; the prompt file is now an artifact that lands on disk before the dispatch, so it is the boundary. A high-confidence hit is decided in Step 2, before anything is allocated — so nothing is written, there is no scratch directory to clean up, and the run degrades straight through the existing [PLAN_REVIEW_DEGRADED] path.
  • Re-review rounds: dispatch per @skills/codex-code-review/references/codex-transport.md § Resume with references/review-loop-plan.md.
  • Secondary — only under --dual: Task agent (Explore or strict-reviewer), prompt follows the same independent-research mandate; runs in background, does not block the Codex gate; a late secondary P0/P1 re-opens the loop. Without the flag there is no secondary and Codex is the gate.
  • codex_fail → fallback carries the gate (adapter exit 1 only — @skills/codex-code-review/references/codex-transport.md § Completion state machine: a pending or unknown completion keeps the gate open with no fallback, exit 2 is a configuration error, and an alloc/cleanup failure is a lifecycle error) (@rules/auto-loop.md § Review Dispatch): decide via scripts/lib/review-dispatch.js (contract:'plan'), record [REVIEWER_FALLBACK] plane=plan from=codex to=contract-neutral-reviewer reason=<…> | <ISO8601>, dispatch contract-neutral-reviewer via Task with references/codex-prompt-plan.md as the governing template (P3 = one retry on a fresh instance), and validate the raw report fail-closed with node scripts/validate-family-sentinel.js plan before adopting its verdict. Only when every carrier is exhausted does the run degrade: emit [PLAN_REVIEW_DEGRADED] and hand the plan to the user — that marker means "no validated verdict exists", never "a fallback reviewed it".
  • The plan text is handed over as a candidate artifact to attack — never as "Claude's conclusion to confirm" (per rules/codex-invocation.md).
Show full SKILL.md (443 more words)Show less
Step 4: Convergence (independent budget)

Decision table applied to the conversation's own round count (never the code/doc review budget):

#ConditionAction
1current_round >= max_rounds (default 5; @rules/auto-loop-project.md ## Plan Review Max Rounds)⚠️ Plan Needs Human + residual findings (never silently pass) — the user arbitrates, so nothing further is owed
2No P0/P1 findings this round✅ Plan Ready → trail summary → ExitPlanMode
3Findings remainRevise plan → re-review (continue loop)

Plateau/fingerprint detection is V2 (OQ-9); v1 relies on the hard cap only.

Step 5: Trail summary (FR-9 / NFR-4)

Default output before ExitPlanMode (3 columns minimum):

markdown
## Plan Review

| Rounds | Findings | Modified sections |
|--------|----------|-------------------|
| 2      | 3 (1 P1, 2 P2) | §Approach, §Risks |

✅ Plan Ready

--verbose: append round-by-round findings. Degraded/skipped runs include the [PLAN_REVIEW_DEGRADED] / [PLAN_REVIEW_SKIPPED] token in this block.

Graceful Degradation (NFR-3)

SourceAction
codex_fail — adapter exit 1 only (@skills/codex-code-review/references/codex-transport.md § Completion state machine; a pending or unknown completion keeps the gate open and dispatches nothing, exit 2 is a configuration error, an alloc/cleanup failure is a lifecycle error)fallback dispatch first (Step 3: contract-neutral-reviewer + references/codex-prompt-plan.md, validated via validate-family-sentinel.js plan); only with every carrier exhausted → output [PLAN_REVIEW_DEGRADED] → proceed to ExitPlanMode
High-confidence secret in plan (Step 2)NO reviewer send → output [PLAN_REVIEW_DEGRADED] → proceed to ExitPlanMode

Degradation never blocks plan mode: the plan is always delivered to the user in the same turn, with a grep-able degradation marker.

Sentinel Namespace (prose contracts)

SentinelMeaning
## Plan ReviewSection discriminator — MUST precede every plan verdict
✅ Plan ReadyConverged, no P0/P1
⛔ Plan BlockedP0/P1 present, loop continues
⚠️ Plan Needs Humanmax_rounds reached without convergence
[PLAN_REVIEW_DEGRADED]Reviewer unavailable or secret-detected (fail-closed)
[PLAN_REVIEW_SKIPPED]User-intent bypass (≠ degraded)

No hook parses these. They are behaviour-layer signals: grep-able in the transcript, read by the model on resume and by the human arbitrating. That is exactly why the namespace still matters —

Forbidden: plan-review output must NEVER contain bare ✅ Ready / ✅ Mergeable / ## Gate: / bare ⛔ Blocked. Those sentinels belong to the code/doc review planes (rules/auto-loop.md § Gate Sentinels), and a plan that quotes one publishes a verdict a later reader can mistake for a code or doc gate result. The prompt templates repeat this constraint to the reviewer.

Verdict precedence when reading reviewer output: check the machine tokens ([PLAN_REVIEW_DEGRADED] / [PLAN_REVIEW_SKIPPED]) before verdict markers — degraded/skipped output quoting a verdict in prose must not lose its flags; then ⛔ Plan Blocked before ✅ Plan Ready, so output containing both verdict markers reads as blocked.

Verification

  • Tier and round cap stated before first dispatch (round counter in conversation)
  • Plan text passed redaction contract before any reviewer send
  • Codex prompt used references/codex-prompt-plan.md (independent research mandate, candidate-artifact framing)
  • Exactly one terminal sentinel in the final output (Ready / Needs Human / DEGRADED / SKIPPED)
  • Trail summary present in final plan output
  • No bare code/doc sentinels emitted

References

  • Codex first-pass prompt: references/codex-prompt-plan.md
  • Re-review loop prompt: references/review-loop-plan.md
  • Rules: @rules/codex-invocation.md, @rules/auto-loop.md (Gate Sentinels)
  • Spec: docs/features/plan-review-loop/2-tech-spec.md

Examples

Input: /plan-review
Action: tier standard, cap 5 → redact → Codex review → loop → ✅ Plan Ready → trail summary → ExitPlanMode

Input: /plan-review --quick
Action: tier quick → redact → single Codex pass → verdict → ExitPlanMode

Input: /plan-review --deep
Action: tier deep → redact → Skill("codex-brainstorm", plan challenge) → equilibrium → verdict

Input: user says "skip review, show me the plan"
Action: [PLAN_REVIEW_SKIPPED] → raw plan → ExitPlanMode

© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/plan-review of sd0xdev/sd0x-harness.

  • SKILL.md
  • references/codex-prompt-plan.md
  • references/review-loop-plan.md

Open the folder on GitHubat commit a4d4bc1

Compare with similar skills

Plan Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Plan Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Plan Review this skillsd0xdev/sd0x-harness192—~3.9kAutomated safety check: PassMIT
Explorexwtro0tk1t-cloud/harness265—~1.6kAutomated safety check: PassNone
02 Implementai-driven-dev/framework513—~404Automated safety check: PassMIT
Plannotator Visual Explainerbacknotprop/plannotator9.2k—~1.7kAutomated safety check: PassApache-2.0
Coding Protocollencx/skills196—~2.4kAutomated safety check: PassMIT
Codex Code ReviewPiLastDigit/TRIP-workflow635—~1.2kAutomated safety check: PassNone

Similar skills

  • Explore

    xwtro0tk1t-cloud/harness

    Graph-driven project understanding using code-review-graph (CRG).

    265 GitHub stars~1.6k tokensUpdated 5 mo ago
    Agent WorkflowsAuto-check passed
  • 02 Implement

    ai-driven-dev/framework

    Write an existing plan's code, phase by phase, until every acceptance criterion holds.

    513 GitHub stars~404 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Plannotator Visual Explainer

    backnotprop/plannotator

    Builds self-contained HTML explainers for plans, pull requests and technical concepts in Plannotator's theme, then opens them in its annotation view.

    9.2k GitHub stars~1.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Coding Protocol

    lencx/skills

    Risk-scaled repo execution and code-evidence protocol. An agent skill from lencx/skills.

    196 GitHub stars~2.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Codex Code Review

    PiLastDigit/TRIP-workflow

    Iterative Codex CLI code review against an implementation plan

    635 GitHub stars~1.2k tokensUpdated 14 days ago
    DevelopmentAuto-check passed
  • Codenote Fix Prompt

    Philip-Cao-9527/code-note-helper

    为 CodeNote Helper 生成普通开发、修复、验证、治理、文档和审核友好类中文执行 prompt。用于把一次具体任务整理成可直接交给 Codex 或 Agent 执行的 prompt;不承载 Plan mode prompt、code review prompt 或项目 skill creator 的完整职责。

    273 GitHub stars~931 tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed

More from sd0xdev/sd0x-harness

All 89 skills in this repo
  • Adr

    sd0xdev/sd0x-harness

    Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…

    192 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Load PR Review

    sd0xdev/sd0x-harness

    Load GitHub PR review comments into AI session — analyze, triage, plan.

    192 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Next Step

    sd0xdev/sd0x-harness

    Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Obsidian CLI

    sd0xdev/sd0x-harness

    Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Orchestrate

    sd0xdev/sd0x-harness

    Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • PR Comment

    sd0xdev/sd0x-harness

    Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.

    192 GitHub stars~1.5k tokensUpdated today
    Auto-check passed

Questions about Plan Review

What does Plan Review do?

Pre-ExitPlanMode adversarial plan review loop via Codex exec. Plan Review is an agent skill from sd0xdev/sd0x-harness. Pre-ExitPlanMode adversarial plan review loop via Codex exec.

When should I use Plan Review?

Plan Review fits situations like: before presenting a plan to the user; reviewing an in-context plan draft.

How do I install Plan Review in Claude Code?

Run `npx skills add sd0xdev/sd0x-harness --skill plan-review -a claude-code`. Or copy the skill folder (skills/plan-review in sd0xdev/sd0x-harness) into .claude/skills/plan-review in your project. Claude Code loads it when a task matches its description.

How do I install Plan Review in Codex?

Run `npx skills add sd0xdev/sd0x-harness --skill plan-review -a codex`. Or copy the skill folder (skills/plan-review in sd0xdev/sd0x-harness) into .agents/skills/plan-review in your project. Codex loads it when a task matches its description.

Can I use Plan Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill plan-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plan-review, .gemini/skills/plan-review, .github/skills/plan-review and .opencode/skills/plan-review in your project.

What does Plan Review need to run?

Going by SKILL.md and its folder, Plan Review needs the command-line tools its instructions call (node). Its frontmatter pre-approves these tools: Bash(bash:*), Bash(git:*), Bash(node:*), Read, Grep, Glob, Task, Skill.

Does Plan Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Plan Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Plan Review use?

Plan Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Plan Review use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Plan Review?

Skills that share tags, products or a category with Plan Review: Explore (xwtro0tk1t-cloud/harness, 265 stars), 02 Implement (ai-driven-dev/framework, 513 stars), Plannotator Visual Explainer (backnotprop/plannotator, 9.2k stars) and Coding Protocol (lencx/skills, 196 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Plan Review?

sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on October 8, 2026.

Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.